Law note · United Kingdom

UK GDPR Articles 33-34 and PECR, Breach Notification in the United Kingdom

cite UK GDPR, Arts. 33-34; Privacy and Electronic Communications Regulations (PECR), as amended by the Data (Use and Access) Act 2025 stage In effect since 2018-05-25 reviewed 2026-08-24

UK General Data Protection Regulation (GDPR) Articles 33 and 34 retain the same 72-hour and without-undue-delay structure as EU GDPR, with no threshold for how serious a breach must be before it is notifiable. The DUA Act shortened the separate PECR breach-notification window for telecoms and ISP-type breaches from 24 hours to 72 hours, in force 20 August 2025, aligning it with the UK GDPR timeline, and raised the maximum PECR fine to GBP 17.5 million or 4 percent global turnover, up from GBP 500,000.

What it asks of an app

  • Notify the ICO without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in the United Kingdom, unless the breach is unlikely to risk their rights and freedoms.
  • Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms, and if you are a telecoms or ISP-type provider, notify a PECR breach to the ICO within 72 hours.

When LexLint raises it

Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics

Primary source: legislation.gov.uk, official consolidated text

← Back to the example  ·  Lint your app →